CVE-2026-80707

Source
https://cve.org/CVERecord?id=CVE-2026-80707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80707
Downstream
Published
2026-08-28T06:53:08.244Z
Modified
2026-08-31T03:30:58.140530162Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

can: j1939: transport: j1939sessionfresh_new(): initialize receive buffer

Zero the allocated buffer in j1939sessionfresh_new() to ensure it contains no residual data.

While there is a potential performance impact if users allocate maximum sized ETP buffers, most real-world use cases are not noticeably affected since the maximum known buffer size is typically around 65K.

[mkl: add Message-ID]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80707.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9d71dd0c70099914fcd063135da3c580865e924c
Fixed
348818277a3646d5b9fa60c9d20c00dc4bc86832
Fixed
f3e120a34b336079479fa10f706f0636eaa6e751
Fixed
bbfa49d1e287de44994955b44d19281be3195b44
Fixed
194d67e92197eb820f4c2c6605d9721333b3eba0
Fixed
038bad8e16c2e28acf31f0b527a816fb23a57269
Fixed
8604a3b81b9d0ceaf04fee5f52e701f623a179f9
Fixed
d5b3613c7d69d8dcb4dd6704f1f463198ce9f6cf
Fixed
eb96c58907922546e415e545fe9a14ea63b02719

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80707.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80707.json"